Verify Wi-Fi isolation in stores: Test shopper Wi-Fi against tills, payment terminals and staff devices.; Confirm isolation using a store-specific diagram and rule list.; Hold acceptance if denied paths are proven blocked and tasks work.
Image: Retail Technology Guide

Store Networks

Part of Retail store networks

Verify shopper Wi-Fi isolation from store systems

Use a store-specific access-path list and witnessed checks to accept, revise or hold shopper Wi-Fi isolation from tills, staff and payment systems.

Before accepting an installed store network, test shopper Wi-Fi against the store’s tills, payment terminals, staff handhelds, administration interfaces and each approved supplier route. A separate Wi-Fi name does not show whether those paths are reachable; acceptance needs a store-specific diagram, rule list and witnessed results.

Map the store's actual paths

Use the final diagram and rule list to identify the installed network-segmentation control and where it separates shopper Wi-Fi from business systems. Match the documents to the installed configuration version; a separate Wi-Fi name alone is not evidence of isolation.

Draw the access point, gateway, business systems and any remote-support connection. Label each device group with the task it must perform. A stockroom handheld might need the inventory service, but not the router’s administration page.

A till might need a receipt printer. The payment terminal’s permitted destinations depend on the payment provider’s design. Do not infer routes just because devices share a counter.

Give the technician a short acceptance list:

Starting pointRequired path to confirmPath that should be blocked
Shopper phone on guest Wi-FiCustomer internet accessTill, stockroom printer, staff service and network administration
Till and approved peripheralsThe sales and printing paths in the store designUnneeded access to other device groups
Staff handheldIts assigned stock or order servicePayment equipment and network administration unless expressly required
Supplier support connectionThe named service, destination and time window approved by the retailerGeneral access to the store network

For this store, use the actual destinations and permitted tasks from its design rather than leaving the table as generic labels. For example, test from a device on shopper Wi-Fi to the store’s named till destination and router administration interface; both should be blocked.

Treat the table as a starting specification, not evidence that a particular store has those controls.

Witness the acceptance checks

With the store’s authorisation, connect a test device to shopper Wi-Fi and confirm its intended internet access. Then test each named business destination and administration interface using the relevant service protocol; a failed ping alone does not prove other routes are closed.

For each path, record the test device, network, actual named destination, expected permitted or blocked result, observed result and configuration version. Keep the final diagram and rule list with the record, and identify the person who accepts any exception.

Have a staff user confirm the approved handheld and till tasks still work. Have the payment provider or installer verify payment paths under the agreed design, and test the supplier connection only against its named approved service, destination and time window.

Before signing off, compare the witnessed results with the store’s diagram and rule list. Accept if required tasks work and denied paths are demonstrated; request a change and retest if an approved task fails or shopper Wi-Fi reaches a business service. Hold acceptance if the supplier route, payment path or evidence is unclear.

A captive portal, hidden Wi-Fi name or shared password does not substitute for those checks.

Keep payment and supplier boundaries explicit

If segmentation is used to reduce PCI DSS scope, the PCI Security Standards Council says an assessor must verify that the controls are effective and working as intended. Guest Wi-Fi separation alone cannot establish the store’s scope or compliance; confirm the actual card-data environment with the acquirer or qualified payment adviser.

When you add a new till, kiosk, printer, access point or supplier connection, update the path drawing and repeat the affected checks. Tie supplier access to a named source, destination, purpose and owner, so a later support request does not silently broaden the route.

Key Compliance Requirements for Network Segmentation

PCI DSS Scope Reduction Requirement
Must be verified by assessor – isolation alone is not sufficient
Australian Cyber Security Framework Guidance
Network segmentation and segregation recommended under ISM guidelines
System Hardening Standard
Implementing network segmentation is a key control for securing systems
Post-Change Verification
Update path drawings and retest after adding new devices or supplier connections

More from Store Networks